Deliverable Format

Sample Security Report

An illustrative view of how an engagement is documented. Every finding is evidenced, rated and paired with practical remediation guidance your engineers can act on.

Three-dimensional penetration testing report with holographic severity badges
Risk Severity

Severity Classification

Illustrative Finding Distribution

  • Critical2

    Immediate risk of significant compromise; requires urgent remediation.

  • High4

    Serious weakness with a realistic exploitation path; remediate promptly.

  • Medium7

    Meaningful weakness usually requiring specific conditions to exploit.

  • Low9

    Limited impact issue that should be addressed in normal maintenance.

  • Informational12

    Observations and hardening opportunities without direct exploitability.

Finding NX-001Critical

Broken Access Control On Privileged Endpoint

An authenticated low-privilege account could reach an administrative function because server-side authorization was not enforced. Illustrative example only.

Finding NX-002High

Insufficient Session Invalidation

Session tokens remained valid after a password change, extending the window in which a stolen token could be reused. Illustrative example only.

Finding NX-003Medium

Verbose Error Responses Disclose Stack Detail

Unhandled application errors returned framework and version information useful for targeting later attacks. Illustrative example only.

Report Structure

What Every Report Contains

Executive Summary

A non-technical overview of the security posture, the most significant risks and the recommended priority of response.

Assessment Scope

The exact systems, domains, applications and infrastructure covered by the written authorization, plus documented exclusions.

Testing Methodology

The recognised methodology, tooling categories, manual techniques and testing window used during the engagement.

Security Findings

Each finding documented with a reference identifier, affected component, technical description and reproduction detail.

Technical Evidence

Request and response excerpts, screenshots and logs that substantiate each finding for your engineering team.

Business Impact

What each finding would mean in practice for data, availability, regulatory exposure and customer trust.

Remediation Recommendations

Specific, prioritized fixes with references to secure implementation patterns and configuration guidance.

Retest Results

Verification of remediated findings after fixes are deployed, with a clear closed or open status for each item.

All findings shown here are illustrative examples created for demonstration purposes and do not represent any real client engagement or system.